CVE-2016-8637
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/08/2018
Last modified:
17/06/2026
Description
A local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'early cpio' is used, such as when including microcode updates. Local attacker can use this to obtain sensitive information from these files, such as encryption keys or credentials.
Impact
Base Score 3.x
5.00
Severity 3.x
MEDIUM
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dracut_project:dracut:*:*:*:*:*:*:*:* | 045 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://seclists.org/oss-sec/2016/q4/352
- http://www.securityfocus.com/bid/94128
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637
- https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4
- http://seclists.org/oss-sec/2016/q4/352
- http://www.securityfocus.com/bid/94128
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2016-8637
- https://github.com/dracutdevs/dracut/commit/0db98910a11c12a454eac4c8e86dc7a7bbc764a4



